six2dez / reconftw
- вторник, 26 января 2021 г. в 00:26:34
Shell
Simple script for full recon
This is a live development project, until the first stable release (1.0) it will be constantly updated in master branch, so if you have detected any bug, you can open an issue or ping me over Telegram or Twitter and I will try to do my best :)
ReconFTW performs automated enumeration of subdomains via various techniques and futher scanning for vulnerabilties, to give you a potential vulns.
git clone https://github.com/six2dez/reconftw
cd reconftw
chmod +x *.sh
./install.sh
./reconftw.sh -d target.com -a
~/.config/amass/config.ini
)~/.config/subfinder/config.yaml
)~/.githound/config.yml
)GITHUB_TOKEN
env var)shodan init <SHODANPAIDAPIKEY>
)COLLAB_SERVER
env var)XSS_SERVER
env var)TARGET OPTIONS -d DOMAIN Target domain -l list.txt Targets list, one per line MODE OPTIONS -a Perform all checks -s Full subdomains scan (Subs, tko and probe) -g Google dorks searches -w Perform web checks only without subs (-l required) -t Check subdomain takeover(-l required) -i Check all needed tools -v Debug/verbose mode, no file descriptor redir -h Show this help SUBDOMAIN OPTIONS --sp Passive subdomain scans --sb Bruteforce subdomain resolution --sr Subdomain permutations and resolution (-l required) --ss Subdomain scan by scraping (-l required) OUTPUT OPTIONS -o output/path Define output folder
These are the last features that we have implemented, take a look at our pending features or suggest a new feature in the issues section:
You can support this work buying me a coffee:
For their great feedback, support, help or for nothing special but well deserved: